Showing posts with label DeFi. Show all posts
Showing posts with label DeFi. Show all posts

Saturday, September 14, 2024

How should money laundering laws apply to DeFi?


Everyone agrees that money laundering laws apply to DeFi. The question is: how to apply them?

DeFi, or decentralized finance, is an emerging segment of the broader financial industry that delivers traditional financial services, say like trading or lending, using a novel type of databaseblockchains.

These blockchains allow people to create financial robots, or bots, that the public can engage with in order to get financial services. And not just any sort of bot. These are autonomous, unstoppable, non-upgradeable financial bots. They operate independently of humans; once its creator sets it free, the bot never needs the intervention of its creatoror anyone elseever again. The bot is unstoppable; once its code is live, it can't be erased, upgraded, or altered. The bot is incapable of deviating from its original code; it is forever locked in place.

(Most financial services provided on blockchains don't quite meet the strict standard described above. These "fake" DeFi bots are upgradeable and are driven by a human operator or team behind the scenes. The application of money laundering laws to fake DeFi bots is straight-forward. What I'm addressing in this post is the true DeFi bots, the ones that are autonomous, unstoppable, and non-upgradeable.)

Historically we haven't received our financial services from autonomous, unstoppable non-upgradeable agents. We've always gotten them from brick and mortar institutions like banks and brokerages. These institutions are run by human executives and employees who rely on a fairly malleable set of machine aids, like websites and Excel spreadsheets and SQL databases.

The application of money laundering law to banks and other financial institutions is well understood. If a bank consciously allows dirty money onto its platform, we punish the bank and the folks who run it. This follows from 18 U.S. Code § 1956, which says that anyone who knowingly conducts a transaction involving dirty money, and does so in a way to conceal its origin or disguise its control, can be punished with up to twenty years in jail for money laundering.

Here's the question: when financial services are provided through the mediation of autonomous, unstoppable, non-upgradeable bots, and not human-operated banks and brokerages, who does society punish when dirty funds are processed? What DeFi party is liable under 18 U.S. Code § 1956?

The bot itself is nonpunishable. It simply keeps on ticking. It's not a human and can't learn from punishment. So that's a dead-end.

There is no human operator or governor to punish (at least, not in the case of pure DeFi bots). The bot is 100% autonomous, operating without the aid of a human behind the scenes.

What about the creator? I've argued in a previous post on a particular DeFi bot, Tornado Cash, that it makes a lot of sense to hold the creators of unstoppable non-upgradeable financial bots accountable for money laundering, even if those creators are no longer involved with the bot in any way. To protect themselves from being charged with money laundering, creators will choose at the very outset to equip their financial bots with a means for screening out dirty funds, thus complying with the law. I'll let you read that post yourself.

There's another option. In a recent exchange with a member of congress, a DeFi lobbyist suggests that the users of unstoppable non-upgradeable financial botsnot the creatorsbe held liable for their own bad conduct. Here's the clip:

This is an interesting solution. Let's work out how money laundering law spreads into DeFi if a user-pays-the-price strategy is adopted.

Say that criminals regularly place dirty funds with a certain DeFi bot, perhaps a decentralized exchange (like Uniswap), in order to clean them, and this is a widely-known fact. Next, let's look at what happens when a user with licit crypto submits their funds to the same bot. By consciously allowing their clean funds to be commingled with dirty funds and swapped for them, these licit users have themselves become bad actors. After all, helping criminally-derived funds make a getaway is a crime: we call it money laundering.

Under this user-pays-the-price scenario, DeFi becomes radioactive. Anyone interacting with an unstoppable, non-upgradeable financial bot is playing with fire, since a potential money laundering charge is just around the corner.

In an effort to reduce the odds that they face a money laundering charge, users may try to shop around for bots that have been coded with filters for screening out bad actors. Creators may try to compete with each other to attract users by providing genuinely compliant bots.

The upshot is that whether society decides to makes creators of financial bots liable for money laundering, or users liable, the end result may very well be the same. Bots will be built with anti-crime devices, thus falling in line with society's money laundering laws. That's a good result.

However, for pragmatic reasons my preference is to hold creators liable rather than users. My mental model of a prototypical retail user of financial services is a frazzled individual who doesn't have the bandwidth or knowledge to grasp exactly what they are doing with their money, because their time is divided between their family, jobs, education, church, hobbies, and other important things. What an awful burden to put on these people: "Oh, by the way, be careful where you get your financial services online, because you might be caught laundering money for the mob." Indeed, one of the advantages of dealing with a traditional bank is that a licit user needn't worry about this hazard.

Creators, on the other hand, are far fewer in number than users, are likely to be financially savvy, and probably have far more time to devote to the intricacies of financial law. And so the creator class will be better able to bear the burden of being targeted with the burden of a potential money laundering charge, and instigating the necessary compliance.

So if we had to choose who to be liable for the bad conduct flowing through unstoppable non-upgradeable financial bots, I say target creators, if possible, and not users. We all agree that money laundering laws apply to DeFithe end goal being bots that exclude criminalsbut placing the liability on users is an an inefficient and unfair way of extracting compliance.

Thursday, August 31, 2023

Who are the money launderers in the Tornado Cash stack?

Over the last few years I've written a bunch of posts about Tornado Cash, an Ethereum-based mixing service, because I find it to be a fascinating tool. With the recent indictment of two people involved in the Tornado Cash "stack" for money laundering, here's another post to add to the list.

Let's get this clear from the outset. Somewhere in the Tornado Cash stack, someone is committing the crime of money laundering. That's been the case since at least mid-2020 or so, the moment that crooks started to send their criminally-derived ether proceeds to Tornado Cash for cleansing.

I'm going to repeat that. One of the parties (or groups of parties) woven together via the Tornado Cash apparatus has been knowingly acting as a financial counterparty to criminals, helping to "conduct" transactions that obfuscate dirty ether.

The question always was: who in the stack is guilty of money laundering? Is it the developers who are  laundering money? Miners? TORN token holders? Relayers? Licit users who engage with the smart contracts? And if so, are all licit users guilty, or just some users? Are the operators of the popular user interface the guilty parties?

A recent indictment from the U.S. Department of Justice claims to have figured out who the money launderers are.
 
Before getting to the indictment, let's tally up all the actors involved in the Tornado Cash stack. To begin with there are the users and developers. The central element of the Tornado Cash stack is a set of smart contracts, or pools, where users  both crooks and non-crooks can send their easily-traced ether to be mixed, getting it back anonymized and untraceable. These core smart contracts were originally coded by three developers in 2019. In mid-2020, the developers removed the core contracts' upgradability, in effect "throwing away the keys" and ending their influence over them.

The next key set of actors are the relayers. Doing stuff on the Ethereum blockchain requires paying a fee to validators. The visibility of these fee payments effectively unwinds Tornado Cash's anonymity and reveals who Tornado Cash's users are. A group of third-party individuals, the relayers, are recruited to handle fees on behalf of users, thus restoring privacy.

The Tornado Cash stack also includes a popular user interface that acts as an overlay over the smart contracts, making them easier to interact with. Control over the user interface is delegated to individuals who own TORN tokens. TORN allows its owners to vote on how the front-end functions, in addition to earning profits from it. TORN holders have no influence over the core smart contracts.

Of these many actors, the DoJ has singled out Roman Storm and Roman Semenov, along with "others known and unknown," as the putative money launderers. (The government also accuses the two of failing to register as a money transmitter, but I'll set that aside.)

Storm and Semenov were the original developers of the core smart contracts, but that doesn't seem to be the nub of the DoJ's money laundering case. Rather, it is the accused's ongoing control over the user interface, exercised through their ownership of a large block of TORN tokens, that seems to have implicated them. Despite knowing that the Tornado Cash stack had become popular with criminals, the owners/operators of the user interface did nothing to screen bad actors from accessing said interface. On the contrary, they made efforts to both improve the interface and increase the profits they made from it.

The government's illustrates this by explaining the involvement of Storm and Semenov in managing the list of relayers that appear on the user interface, as well as in crafting the system for rewarding and levying fees on these relayers. The indictment cites a vote made by TORN holders in early 2022 that led to an update of the user interface's mechanism for listing relayers. The change allowed anyone to appear on the list, as long as they could stake a certain quantity of TORN tokens. The DoJ alleges that this decision improved anonymity by lengthening the user interface's list of relayers.  

The indictment further alleges that Storm and Semenov, through their ownership of TORN, profited financially from the user interface's new method of listing relayers. To get on the user interface list, a relayer had to buy TORN, which pushed up TORN's price. In addition, whenever a relayer that appeared on the user interface's list was selected, a portion of that relayer's staked TORN was "slashed," or reduced, forcing relayers to top up with additional TORN purchases in order to continue to qualify for the list. This added more upward pressure on TORN's price to the benefit of holders like Storm and Semenov.
 
In the government's view, the totality of these actions constitute money laundering, specifically a violation of  18 USC § 1956. The DoJ believes that the two defendants "conducted" transactions, a key element of money laundering, via their ongoing control over the user interface, along with other TORN owners. The indictment also shows that a large portion of Tornado Cash transactions were in fact criminal proceeds, including those made by the Lazarus Group. (I mean, we all knew that already.) Lastly, they show that the accused were aware that the funds coursing through the Tornado Cash stack were dirty, a mental state of knowing being a key plank in charging someone for money laundering.

It seems to me like the DoJ has a solid case, although we can debate whether operating the Tornado Cash user interface and its relayer list is tantamount to "conducting" transactions. The legal definition of conducts is a broad one, including "participating in initiating, or concluding a transaction." While the user interface, and thus those who operated it, never directly initiate transfers of ether to the underlying Tornado smart contracts, it doesn't seem a stretch to describe them as participating in the initiation of those transfers. We'll have to see what the judge says.

Counterintuitively, the indictment seems like a win, if only a lukewarm one, for fans of decentralized finance, or DeFi.

Proponents of DeFi have long worried that developers of autonomous smart contracts might be held liable in court for crimes. In this case, however, the same actors who happen to be the developers of Tornado's core smart contracts also built a complex and centralized business structure around those same contracts, and it is this tertiary apparatus that is serving as the basis for a money laundering charge, not the original coding of the core smart contracts.

It's a useful thought experiment to imagine how things might have played out if Storm and Semenov had acted differently. Let's imagine that the two coders hadn't created a profitable apparatus around the original smart contracts. Once the core smart contracts were up and running, they ceased to associate in any way with the Tornado Cash stack. Secondly, imagine there was no user interface. To deposit or withdraw funds, users had to interact directly with the smart contracts. Lastly, let's assume that TORN tokens had never been issued, so there was nothing to govern (or govern with), and thus no basis for the government to use "operating control" as a lever for a money laundering prosecution.

Given a very slimmed-down Tornado Cash stack, who does the DoJ now accuse of money laundering? Because they have to accuse someone. Crooks depositing dirty ether are still ending up with laundered ether, so there is by definition a "someone" in the stack who is providing laundering services to them.

In our hypothetical story, Storm and Semenov are not the money launderers, and the thrust of the DoJ's indictment confirms this. The two developers created software with presumably noble intentions: to provide regular folks with privacy from the panopticon that is Ethereum. Then they walked away, leaving the tool indelibly etched on the blockchain. It was only then that people started to interact with the tool, some of them to carry out illegal activity. It's this latter group who constitutes the guilty party.

Relayers are excellent candidates for a money laundering charge, a point I made last year. Because they process withdrawals on behalf of users, it would likely be a cinch to pin them for "conducting" transactions. Showing that relayers do this despite knowing that criminals may be their counterparties shouldn't be difficult for prosecutors to establish. And indeed, the DoJ's actual indictment is going in the right direction when it says that Storm and Semenov, along with "others involved in the Tornado Cash service, including the relayers," were engaged in the business of transferring funds, and goes on to accuse these "others," presumably relayers, of engaging in money laundering.

The second logical target for a money laundering charge is the licit users of Tornado Cash, in particular the large and savvy ones who used the tool regularly. A person who is aware that criminals are depositing dirty money into Tornado Cash smart contracts, yet decides to deposit their own funds into those same smart contracts, knowing that their effort will help these criminals conclude transactions that disguise the source of their funds, ticks all the boxes for a money laundering charge.

A licit user of Tornado Cash accused of money laundering might try to wiggle out of the charge by saying: "Sure, I knew crooks were using Tornado, and I know my efforts helped them. But I was only using it for legal reasons. I wanted to get privacy for myself." But that's not a very good defence against a money laundering charge, for the same reason that someone who tries to make a profit from obfuscating criminal funds can't evade a money laundering charge by saying they were only motivated by profit, and profits are legal. The desire to improve one's position, whether that be to get privacy or profits, isn't an excuse to launder money for crooks.

To sum up, the task of any prosecutor trying to bring money laundering charges against the Tornado Cash stack is to find the actual third-parties who misuse the platform for laundering. In a slimmed-down Tornado, that means chasing down relayers and savvy licit users. In the DoJ's actual indictment, it's also trying to show that owners/operators of user interfaces qualify, and while it's not a bad theory, we'll have to wait for the court date to see if it gets confirmed.

Tuesday, January 10, 2023

Why the steepest borrowing rate may be the best rate

(This isn't a piece of financial advice. It's more of a fun parable about interest rates.)

So here's an interesting financial riddle. Let's say I want to buy a used car for $1000. 

First, I need a loan. Say that there are two floating rate loans available to me: one that currently costs 3.2% per year, and another that costs 2.3%. Logic dictates that I should take the cheaper 2.3% option, right? But I don't. Instead I take the more expensive one, figuring to myself that the expensive 3.2% loan is actually the cheaper loan.

Why on earth did I do that?

The rates in question are from the website for Aave, a tool for borrowing and lending cryptocurrencies, including stablecoins:

The cost of borrowing two different stablecoins on Aave [source]

If I borrow 1000 Tether stablecoins from Aave to fund my purchase of the $1000 car, it'll cost me 3.2%. But if I borrow 1000 USD Coins, it'll cost me just 2.3%. Those are floating rates, not fixed. (I could also borrow stablecoins on a fixed basis. A fixed-rate Tether loan would cost me 12.26% on Aave, a USD Coin loan 10.69%. Again, it's more expensive to borrow Tether.)

Why would I pay 3.2% to borrow one type of U.S. dollar, Tether, when I can get another type of U.S. dollar, USD Coin, at a cheaper rate? I mean, they're both dollars, right? They each do same thing; that is, they both provide me with the means to buy a $1000 car.

To see why I might prefer the more expensive Tether loan, we need to understand why the rates on Tether and USD Coin differ:

If I borrow 1000 stablecoins to buy a $1000 car, eventually I'll have to buy those 1000 stablecoins back in order to repay my loan. Wouldn't it be nice if, in the interim, the stablecoin I've borrowed loses its peg and falls in value? Because if it were to do so, I'd be able to buy back the 1000 stablecoins on the cheap (say for $400 or $500), pay back my 1000 stablecoin loan, and keep the $1000 car. 

In short, I'd be getting a $1000 automobile for just $400-$500 plus interest.

By contrast, if I were to borrow a more robust stablecoin in order to purchase the car, then that'd reduce the odds of its price being weak when it comes time to repay my loan, thus making the entire transaction more expensive to me. 

A $1000 car would cost me... $1000 plus interest.  

We can imagine that all potential borrowers are perusing Aave's loan list with that exact same thought in mind. Jack wants to finance a house for $250,000 by getting a stablecoin loan on Aave. Jane wants to borrow $100 in stablecoins on Aave to pay off her credit card debt. All three of us would really, really, really, like to borrow a stablecoin that fails, reducing the net cost of our purchase. So we all do our respective research and select what we believe to be the stablecoin with the worst prospects, the one most likely to be worth just 40 or 50 cents when it comes time for us to repay our debt.

The competition between the three of us to borrow the worst stablecoin will cause borrowing rates for the worst stablecoins to rise. Conversely, borrowing rates on the stablecoins with the best prospects will fall.

And that's what I suspect is happening on Aave. Tether is seen as the riskier stablecoin. And so from the perspective of the borrowing public, a Tether loan is superior to a USD Coin loan. Jack, Jill, and myself are all scrambling for the privilege of borrowing Tether, in the process pushing the cost of borrowing Tether 0.9% above the cost of borrowing USD Coin.

Now we can get back to the original riddle. Even though the rate to borrow Tether is higher than the rate to borrow USD Coin, it may be worthwhile for me to go with the a Tether loan if I think that the odds of Tether failing justify the higher financing cost.

We can even go a bit further and say that the 0.9% premium on a Tether loan is the market's best estimate of the odds of Tether losing its peg relative to USD Coin losing its peg. So for all those would-be stablecoin analysts out there, keep your eye on Aave's USD Coin-Tether spread. It's a good indicator of stablecoin risk.


P.S: The difference between the cost of borrowing Tether and USD Coin could also be due to the liquidity premium on Tether being larger than the liquidity premium on USD Coin. I'm not going to get into that possibility in this post, but if you're curious ask me about it in the comments. 

P.P.S: Does this same logic apply to borrowing from banks? Would I rather borrow from a bank that's about to fail rather than a solid respectable bank?

P.P.P.S: Some Dune dashboards tracking he Tether-to-USD rate premium: here and here.

Thursday, October 13, 2022

Stablecoins, meet 3% interest rates


The global rise in interest rates is finally beginning to percolate into the stablecoin sector. One of the effects of this rise is that centralized stablecoins like USD Coin and Gemini Dollar, which by default pay 0% to holders, are introducing backdoor routes for paying interest to large customers. (See my tweets here and here).

In the case of USD Coin, Coinbase refers to interest as a "reward." Gemini calls it a "marketing incentive." But less face it: they're really just interest payments.

The links I provide are the only public evidence of stablecoins doling out interest, but you can be sure that behind closed doors, large issuers like Circle/Coinbase, Gemini, and others are offering their largest customers -- in particular exchanges like Binance and Kraken -- the same deals.

Stablecoin issuers are offering interest to select customers because of the inexorable pressure of competition. After hovering near 0% for much of the last decade (see chart above), interest rates have ramped up to 3% in just a few months. Issuers hold assets to back the stablecoins that they've put into circulation, and now these previously barren assets are yielding 3%. That means a literal payday for these issuers. In the first quarter of 2022, for instance, Circle (the issuer of USD Coin) collected $19 million in interest income after making just $7 million the quarter before. In the second quarter of 2022, interest income jumped to $81 million. I suspect the third quarter tally will come in well above $150 million.

However, if they don't share at least some of this juicy reward, issuers risk having their customers flee to alternatives that do offer interest, like Treasury bills or corporate deposit accounts. And then the amount of stablecoins in circulation will shrink, eating into issuers' revenues.

And thus, we get to a world where Gemini is promising incentives and Coinbase rewards.

Alas, while large stablecoin holders may be benefiting from this trend, small holders of stablecoins are being ignored. They don't get to share in these sweet flows of interest income. Even folks with old-school U.S. savings accounts are being paid 0.17%!

Small stablecoin holders need to unite. By working together through a StablecoinDAO, their bargaining power vis-a-vis the big stablecoin issuers improves. They may be able to negotiate the same interest payments from Circle and other issuers that large stablecoin customers are getting.

For a good example of strength in numbers, take a look at the phenomenon of high-interest savings ETFs in Canada. Corporate customers of Canadian banks get far better interest rates on chequing deposits than retail customers do. A high-interest savings ETF manager bridges this divide. They collect money from retail customers, invest the proceeds in banks at the corporate rate, and then share the superior return with thousands of retail ETF unit holders.

A StablecoinDAO would work along the same lines as a high-interest savings ETF. People would deposit their stablecoins -- USD Coin, Gemini Dollar, Binance USD, USDP, Tether, Dai -- into a smart contract. In return they'd get a new stablecoin called, say, UniteUSD, which would be redeemable on demand into any of the DAO's underlying stablecoins. UniteUSD itself would be useful. It could be used for purchases, deposited into smart contracts, or traded on decentralized exchanges and whatnot.

StablecoinDAO would have the authority to swap one underlying stablecoin out with a new one. That potential threat would give the DAO the necessary leverage to negotiate interest payments. "Hey Circle, if you don't pay us 1% then we're going to shift the DAO's holdings over to Binance USD, your competitor." As a nuclear option, the DAO could threaten to buy short-term government debt.

The interest that the DAO receives would be funneled back to UniteUSD holders. 

In sum, that's how interest rates finally filter through to small stablecoin owners.



A few random afterthoughts about stablecoins and interest payments, in no particular order:

* A version of StablecoinDAO may already exist... in the form of MakerDAO, a decentralized-ish bank that issues Dai stablecoins. Think of MakerDAO as an organizing device for small stablecoin customers to extract interest from stablecoin issuers. These small holders deposit their stablecoins (USD Coin, USDP, etc) into MakerDAO smart contracts and receive Dai stablecoins in return, which are convertible to any of these underlying stablecoins on a 1:1 basis. MakerDAO negotiates with issuers for interest payments, sluicing this interest back to Dai owners.

* Some tricky regulatory issues arise when retail customers are promised a return. If StablecoinDAO were to pay interest on UniteUSD, then UniteUSD might be deemed to be a security, and thus StablecoinDAO would have to register with a securities agency. This could doom StablecoinDAO, or at least make things very difficult for it. (Remember, when PayPal used to pay interest to customers? It did through an SEC-registered money market mutual fund.)

* StablecoinDAO would become a stablecoin black hole: all other stablecoins would quickly get sucked up into it. Why? In a world where USD Coin and USDP can only pay 0% to small stablecoin holders, but depositing said coins into StablecoinDAO means earning 2%, then every small holder will deposit their funds into StablecoinDAO. The DAO would inhale the big stablecoins -- USD Coin, Binance USD, Tether, etc -- right out of circulation, leaving UniteUSD as the dominant stablecoin.

* As competition forces large issuers to share the interest they earn, this will have implications for the finances of those very issuers. Circle, the issuer of USD Coin, envisions being profitable in 2023, as the table below illustrates:

Source: Circle Q2 2022 financials [link]

A big part of Circle's estimates are based on higher flows of interest from the assets that it holds to back USD Coin. What this table isn't accounting for is the concurrent pressure to share interest income with USD Coin holders, both large and small ones, which threatens Circle's 2023 projections.

Monday, February 7, 2022

Why stablecoins should not be regulated like Western Union

Here's an interesting bit of stablecoin trivia. Half of all Paxos stablecoins are currently lying inert in MakerDAO, a decentralized finance protocol. Half!

Founded in 2018, Paxos Standard, or USDP, is one of the elder stablecoins. Overseen by the New York Department of Financial Services, and backed by dollars held in insured banks and Treasury bills, Paxos Trust has issued $1.03 billion worth of its USDP stablecoins into circulation (according to its last attestation report). Of that, $499,996,054 currently sits in MakerDAO (see below).

$499 million USDP in MakerDAO

This data point is useful for illustrating how stablecoin issuers like Paxos Trust should be regulated.

We should be regulating financial products on a functional basis. That is, if a financial instrument or financial venue functions in a certain way, we should have a regulatory framework that oversees that function, and everything that functions similarly should fall under that framework, and everything that doesn't should be caught by a more appropriate framework.

Common sense, right?

So how are stablecoins being regulated in the U.S? One of the many frameworks that has been adopted is existing state-based money transmitter law. The biggest stablecoin USD Coin is issued by Circle Internet, a company that is licensed by around 40 different states to transmit money. Oddly, this is the same regulatory framework that applies to old-school remittance companies like Western Union. If you've never made a remittance before, here's how it works. A retail customers temporarily hand over a small amount of money, say $200, to a Western Union agent. The agent contacts a foreign Western Union office and tells them to provide cash to the customer's friend or relative.

In the early 2000s this money transmitter framework was expanded to cover the likes of PayPal. Whereas Western Union keeps customer funds for an hour or two, tops overnight, customers of PayPal keep balances in their wallet for months, even years. 

This storage function means that PayPal is doing something quite different than Western Union. And so the subsuming of PayPal (and other wallet providers like Venmo and Square Cash) under state money transmittal law in the early 2000s was probably a failure of functional regulation. A wallet business and a remittance business should be differently regulated. 

This mistake was unfortunate. Zooming forward to the 2020s and the dawning era of stablecoins, one hopes the same mistake is not made again. What function is being performed by the $500 million Paxos stablecoins locked inside MakerDAO? Not Western Union-style remittances. Not PayPal-style personal wallet services. Paxos stablecoins are serving as the building blocks for core decentralized financial infrastructure. If Paxos fails, the entire MakerDAO edifice experiences a deep shock, this effect cascading to all the secondary tools based on MakerDAO and from there to all the tertiary tools based on those secondary tools.

In a sense, the role being played by Paxos stablecoins is the same role being performed by Treasury bills and other safe assets like commercial paper or money market funds, which are the foundational bedrock for all sorts of traditional financial services.

Now, there is another $500 million worth of Paxos stablecoin that is not frozen in MakerDAO. This block of stablecoin may very well be serving a different function than the half billion block locked in Maker. (For instance, I hold $100 in Paxos tokens, and I suppose they function very much like the $100 I hold at PayPal.) But the key point is that while there are times when stablecoins function like PayPal and Western Union, in other circumstances they are performing a role that PayPal and Western Union never do, which is to serve as the substructure for a set of financial utilities. Which suggests that stablecoins merit a different regulatory framework, one better fit for that function.

I don't know what framework that should be. Banking, securities law, a special stablecoin license? But the old school money transmitter framework – which has very lenient requirements governing things like the safety of the transmitters underlying assets – is probably the wrong framework. If you serve as financial bedrock, you merit more robust regulation than Western Union. 

(And by the way, Paxos Trust is itself not regulated as a money transmitter. It operates under the NYDFS's stablecoin framework, which is stricter than money transmitter law, and may be sufficient).

Saturday, January 29, 2022

DeFi needs more secrecy, but not too much secrecy, and the right sort of secrecy

[Below is my contribution to CoinDesk's Privacy Week

The Privacy That DeFi Needs to Succeed

The transparency of blockchains is often marketed as a benefit. It's not. Main Street financial consumers are never going to adopt blockchain-based financial tools as long as blockchains are radically transparent. Regular folks have secrets that they want to keep.

One of the most promising use cases for blockchains is decentralized finance (DeFi). The people who are building DeFi tools aspire for DeFi to be something more than a skate park for the risk-loving crypto-rich. They want their tools to solve real-world financial problems faced by individuals and companies, including America's 31.7 million small businesses.

Imagine a cash-starved manufacturer in Toledo, Ohio, that has a good idea for a product. It could go to its banker for financing, but instead it turns to DeFi. In a jiffy, it tokenizes a bunch of receivables onto a blockchain and lodges them as collateral on a decentralized lending platform in return for U.S. dollar stablecoins. A few moments later, it swaps these dollars for Euro stablecoins using a decentralized exchange, sending them to its French supplier to purchase inventory.

This chain of transactions has the promise of being cheap, fast and avoiding the walled garden of regular banks. Unfortunately, our Toledo manufacturer probably won’t bother.

All blockchain transactions are public by default. The government, your competitors and your mother can all see what you are doing. Blockchain analytics firms like Chainalysis and CipherTrace make it their business to track, analyze and interpret every trade and transaction.

Secrecy is vital to commerce. Not only is it important for businesses to protect the privacy of their customers, they must also keep their competitors in the dark lest their long-term strategy be divined and countered or copied. Our Toledo manufacturer doesn’t want its intentions to be telegraphed by their on-chain financial preparations.

As for individuals, they don't want their friends and colleagues to know what their salary is, or what kinds of porn they're purchasing. No one wants to be doxxed. We like our secrets.

Bricks-and-mortar finance is already capable of providing the secrecy that Main Street requires. Individuals and corporations generally trust their old-school bankers not to reveal information about their financial dealings to others. It's not quite cash-level anonymity. Yes, there are leaks and hacks. And under certain conditions, a banker must disclose information to law enforcement. But in general, Main Street trusts the confidentiality and probity of their financial provider.

So if Main Street users are ever going to migrate over to DeFi, privacy will have to be built first. But not just any privacy.

Tornado Cash has become the DeFi world's go-to tool for achieving anonymity. A user can send funds to a Tornado Cash smart contract where it gets mixed up and obfuscated with other people's funds. Later, that user can surreptitiously withdraw the same amount of money to a separate address. A technology called zk-SNARKs is used to reduce the ability of third parties to trace funds through Tornado.

Unfortunately, Tornado Cash has become a popular venue for thieves to clean stolen funds. The presence of criminals will make Main Street businesses like our Toledo-based manufacturer hesitate. Depositing company funds into a Tornado Cash smart contract may be construed as mixing them with criminally-derived funds. That's probably not the sort of money laundering risk that licit money wants to take.

The best solution for bringing privacy to DeFi is native anonymity. That is, all blockchain transactions have to be opaque by default. That way, Main Street users get the privacy they require without having to take the risk of jumbling up their coins with crooks. (Approaches like the Aztec Network, a privacy layer implemented on top of the base Ethereum layer, might be a solution.)

While native anonymity would solve Main Street's very real need for secrecy, it will lead to the next hurdle to widespread adoption: too much anonymity.

If a Main Street financial user like our Toledo manufacturer can't risk tumbling their coins with dirty money on Tornado Cash, neither can they risk commingling their funds on decentralized exchanges or lending tools that grant unconditional access to everyone, including thieves' dirty funds.

To make their tools palatable for Main Street, DeFi tool makers will have to unwind some of the native anonymity (potentially) afforded by blockchains by collecting and verifying identifying information from users. This way the tools can screen out criminals, assuring legitimate businesses that their clean funds aren't being tainted by dirty money.

The implication is that DeFi tools will have to become privacy managers, just like old-school banks are. Users will have to trust the tools to be discreet with their personal information, only breaking their privacy when certain conditions are required, such as law enforcement requests.

It’s possible that DeFi succeeds in doing a better job of preserving privacy than traditional financial institutions. By using zero-knowledge proofs for collecting identity, DeFi tools may be able to control the spray of personal information required to gain access. This may reduce the amount of information that gets lost to hacks.

In sum, if DeFi wants to attract Main Street users, an odd mix of more secrecy and less secrecy is required. Secrecy is important to businesses and individuals. They don’t want their information to be naked for all to see. But Main Street doesn't want complete anonymity. It wants to use DeFi tools that strip away just enough secrets to assure that dirty money is being excluded.

Only when this balance has been achieved will businesses like our Toledo, Ohio, manufacturer venture onto the blockchain.

Monday, January 3, 2022

Should central bankers be afraid of crypto?

As crypto continues to move into the public's consciousness, curious people who aren't familiar with it often ask me if central bankers at the Bank of Canada or the Federal Reserve should be worried that crypto may replace the dollar. 

In this short blog post I'll suggest that they should not be worried.

For central bankers like the Fed's Jay Powell or the Bank of Canada's Tiff Macklem, controlling national monetary policy is probably their most important task. By altering the money supply or shifting interest rates, Powell influences the value of U.S. dollar. These policy changes get transmitted across the entire country thanks to the ubiquity of the U.S. dollar as a unit for expressing prices. (For his part, Macklem relies on the Canadian dollar's dominance as a unit-of-account in Canada to exercise monetary policy). 

Monetary policy is important. First, it keeps the dollar's purchasing power stable. Since our wages and contracts are denominated in dollars, a degree of sameness and consistency is important. Second, monetary policy is an important tool for offsetting broader economic shocks, say the pandemic or the '08 financial crisis.

Given that crypto is often marketed as a dollar replacement, might Powell and Macklem be losing some sleep? After all, if crypto starts to replace the dollar as America or Canada's unit-of-account then neither central banker can carry out national monetary policy.

Luckily for Powell and Macklem, crypto is not a threat to the dollar.

Crypto is no longer a very useful term, since it encompasses so many different types of phenomena. There is bitcoin, programmable blockchains like Ethereum, stablecoins, non-fungible tokens (NFTs), decentralized finance (DeFi), and more.

Let's start with Bitcoin. In this category I've included other volcoins like Dogecoin, Shiba Inu, Bitcoin Cash, and Litecoin. I call them volcoins because they are incredibly volatile.

In the early days, many of us thought it possible that Bitcoin might develop into a legitimate threat to the dollar. But enough time has passed now that we know this isn't case. The dominant reason people have for owning volcoins is to get exposure to their exciting price moves. That is, volcoins are a gambling technology, not a monetary technology. Rather than competing for dominance with the relatively stable payments instruments issued by central banks, volcoins serve as substitutes for casinos, meme stocks, lotteries, poker, and OTM options. None of these bets will ever be a credible threat to Fed or Bank of Canada dollars.

Let's move onto stablecoins. Whereas volcoins are wildly unstable, stablecoins are the tamer version of crypto. The stability of stablecoins means that they could credibly replace banknotes issued by the Fed and Bank of Canada.

Even if stablecoins become widely used, they won't subvert Powell and Macklem's ability to conduct monetary policy. Because they are pegged to central bank money, stablecoins effectively do the opposite: they extend central bank monetary policy power into blockchain environments. Stablecoins are therefore allies of the Fed and Bank of Canada policy makers, not enemies, in the same way that regular banks such as TD Bank or Wells Fargo are allies because they extend the range of central bank monetary policy into the regular economy.

[Yes, stablecoins involve financial stability issues. But this post is about monetary policy, not financial stability.]

Nor is decentralized finance, or DeFi, a threat to monetary policy. DeFi is just another component of a nation's financial edifice, albeit more decentralized than the other bits. If a stock exchange like the NYSE or Toronto Stock Exchange is no threat to monetary policy, then neither does a decentralized exchange such as Uniswap pose a threat.

Finally, NFTs are a hyperfinancialized claims on underlying digital art. Art never has been a threat to monetary policy and never will be.

In sum, Jay Powell and Tiff Macklem may have reasons to worry about crypto, but concerns of monetary policy impotence should not be one of those worries. Crypto is not going to replace the dollar anytime soon.

Friday, December 10, 2021

Tornado.cash and money laundering


All Ethereum transactions can be tracked.

But there is a neat little tool that lets you remove this traceability: Tornado.cash. Alice submits her Ethereum tokens to a Tornado.cash smart contract where it gets commingled and mixed up with other people's tokens, then re-sent back to Alice at a separate address. (There are some extra things that happen, too. Read here.) Voila, the transaction trail has been obfuscated. All that an outside observer knows is that Alice's coins have been sourced from Tornado (for the rest of this post I'll use Tornado and Tornado.cash interchangeably). They know nothing about their history before then.  

Who uses Tornado? 

Some users are hobbyists and advocates of anonymity. They're not engaged in anything illegal. They want to consume privacy as a financial service. We'll call them legitimate users.

The other batch of users are criminals keen to hide the provenance of the Ethereum tokens that they've stolen by hacking or exploiting exchanges and other financial tools. When BitMart, an exchange, was hacked on December 4, $200 million was laundered through Tornado.cash. A few days later, $1.75 from an 8eight Finance exploit was processed by Tornado. (If you want more examples, ask me in the comments).

My question is this: given the presence of criminal funds on Tornado.cash, is it dangerous for legitimate users to connect to it? More specifically, does a legitimate user who submits their Ethereum tokens to a Tornado smart contract risk a money laundering conviction given that they may be interacting with criminally-derived money?

In the U.S., an individual can be convicted of money laundering if they knowingly conduct transactions in criminally-derived funds. For example, if Joe, a car dealer, sells a Lexus to a criminal for $75,000 in dirty cash, and knows that the transaction was made for the purposes of evading the authorities, then Joe can be found guilty of money laundering. It's a serious offence punishable with up to 20 years in jail.

Would the same principles apply to Tornado.cash users?

If a thief steals some Ethereum and deposits it into a Tornado smart contract where it is commingled with deposits made by a legitimate user, and this legitimate user withdraws their portion of that amount, then it seems to me that the legitimate user may have engaged in money laundering. That is, it's possible that they have conducted a financial transaction that involves the proceeds of an unlawful activity.

But that's not quite enough to establish money laundering. As I said earlier, to be convicted of money laundering a mental state of knowing has to be proven.

Many legitimate Tornado users interact with the tool without knowing much about it. They've never considered the possibility that by connecting to Tornado, they may be serving as a nexus for the laundering of criminally-derived property. Since knowing can't be established, then these users probably can't be judged guilty of money laundering.

But other legitimate users are not so unwitting. It's common knowledge that hacks and thefts are laundered on Tornado.cash. Some of the larger and more savvy Tornado users are no doubt aware that by commingling their funds in a Tornado smart contract they are providing criminals with a means of concealing the source of proceeds of unlawful activity. With knowing having been established, it's possible that their usage of Tornado.cash transcends into money laundering.

But even if the mental state of knowing can be established, one thing is still missing. There doesn't seem to be a clear and well-defined exchange of dirty crypto for clean. That is, when some stolen Ethereum gets deposited into a Tornado smart contract along with legitimate Ethereum, and then later withdrawn, there doesn't seem to be any way to explicitly link the withdrawal of that stolen Ethereum to a specific person. It's hidden by the software.

Put differently, there's no smoking gun.

I think it might be useful at this point to introduce an analogy using physical cash. It is clearly illegal for Joe, our auto-dealer, to knowingly take a criminal's $75,000 in cash. But let's imagine that Joe and the criminal decide to interpose a cash mixing box between themselves. Joe figures that this mixing box will allow him to receive payment without actually taking the criminal's banknotes. Does that make it legal?

It works like this. Two third-parties – Ted and Alice – put in $75,000 in "clean" cash into the mixing box. The criminal puts his dirty $75,000. Ted and Alice's $75,000 gets mixed with the criminal's $75,000. Ted and Alice each remove $75,000. Joe, the auto dealer, also removes $75,000. Joe then transfers the criminal the car.

There is no way for law enforcement to prove that the actual banknotes that Joe has received are the specific banknotes that were deposited by the criminal. Because they were commingled with legitimate money, Joe can deny having accepted criminally-derived funds. (As can Ted and Alice).

But does this set up absolve Joe of guilt? I doubt that the interposition of a cash mixing box would be perceived by a judge as altering the underlying relationship between Joe and the criminal. The mixing box would rightly be seen as a contrivance to throw the cops off. (See last footnote, below)

What about Ted and Alice? If Ted unwittingly contributes his $75,000 to the mixing box – i.e. he doesn't realize that he is helping to obfuscate the criminal's funds – then he probably wouldn't be found guilty of laundering money.

Alice, however, suspects that her contribution to the mixing box will be used to obfuscate the transaction trail between the criminal and Joe, but contributes anyways. The establishment of intention surely increases Alice's odds of a money laundering conviction. She might hope that she can get off because the commingling provided by the mixing box breaks the cash trail between her and the criminal. But again, there's a good chance the judge won't buy this argument.

It's important to keep in mind that Alice may have her own specific reasons for using the cash mixing box. Perhaps she values privacy and therefore periodically mix up all her notes. Maybe she likes to collect certain banknote serial numbers (i.e. ending in 2) and a cash mixing box is a convenient way for her to get exposure to a broad range of potentially collectible pieces.

A judge would somehow have to balance Alice's legitimate reasons for using the mixing box against the fact that she has knowingly conducted transactions in criminally-derived property. Is her right to pursue a peculiar hobby more important than protecting the public's welfare? I'm not sure how that balancing act would end up.
 
Bringing this back to Tornado.cash, I do wonder how safe it is to be a Alice. That is, I wonder how safe it is to be someone who knows that there are stolen Ethereum tokens inside Tornado smart contracts looking for an exit, yet despite the presence of this taint contributes Ethereum to that contract anyways. Even if Tornado obscures any explicit link between Alice and criminals, a judge could look past that.

Alice may say that "I used Tornado.cash because I value my financial privacy." This may be an adequate defence. Maybe not.

Clouding the story is the fact that Tornado.cash is currently paying a juicy financial reward to anyone who puts their cryptocurrency into its smart contracts. (See this video). The fact that Alice is earning 30-40% a year might make her claim to be a mere consumer of financial privacy less credible.

Perhaps one day we'll see a court case where this all gets thrashed out. A decent result would be if a judge ruled in favor of Alice, or at least partly so. The judge suggests that any incidental laundering of funds on Tornado.cash by licit consumers of privacy (like Alice) should be a non-criminal matter, subject to limit. Consider how several U.S. states have decriminalized the possession of small amounts of marijuana for personal use. In that same vein, a fixed amount of intentional commingling of funds on Tornado should be tolerated, the judge suggests, but only for the purposes of personal consumption. Anything above that would remain a felony.



PS: Privacy advocates, please don't shout at me that money laundering laws are unethical. I am making a positive claim here, not a normative claim. That is, I'm not suggesting how things *should* be, but how they actually are. And my positive claim is that there is a risk, perhaps only a small one, that a legitimate user of Tornado.cash could be accused of money laundering. Yes or no?

PPS: Notice that I am no making the claim that Tornado.cash is itself engaged in money laundering, or that the people who have written the Tornado smart contracts are money launderers. I'm treating Tornado.cash as mere software, a digital hammer. A hammer doesn't break the law, people do. My assumption in this post is that society's rules against money laundering fall on the *users* of this software, not on the software itself or on the people who have developed the software.

PPPS: For software developers, if my positive claim is accurate (i.e. that it is risky to use Tornado.cash), is there a way to redesign the software that would solve the problem? More specifically, is there a way to limit the tool to licit users i.e. those who have a legitimate desire to consume anonymity, and keep out criminals? 

PPPPS: It's worth giving U.S. money laundering laws a read. Two of the big ones are located at 18 U.S.C. § 1956 and 18 U.S.C. § 1957. See here.

PPPPPS: On commingling... "Moreover, we cannot believe that Congress intended that participants in unlawful activities could prevent their own convictions under the money laundering statute simply by commingling funds derived from both 'specified unlawful activities' and other activities." U.S. v Jackson, 1991

Tuesday, November 16, 2021

The dangers of stablecoin lending

 

These days I see many do-it-yourself investors comparing the huge yields they can earn on stablecoin lending to the tiny yields on bank accounts. Cryptocurrency influencers like to draw attention to this big gap, portraying crypto as the heroic replacement to stodgy regular finance, or "TradFi". The Celsius Network, one of the leading providers of high-yield stablecoin products, uses the slogan "Unbank yourself." The implication is that anyone who holds their money in a bank account is a chump.

Beware, DIY investors. These marketing pitches are wrong, indeed dangerous. 

In finance, a juicy yield is almost always associated with big risk. Shifting finance to blockchains doesn't change this truth. High-yielding stablecoin strategies are not a better sort of bank account. Rather, they're a potentially hazardous investment more akin with penny stocks and CCC-rated junk bonds.

Let me explain with a recent example:

The premise of this tweet and the attached chart is that you can make far more on your stable crypto dollars than on old fashioned dollars stuck in a bank account.

The problem with this comparison is that it's not contrasting equal things. It's comparing apples to oranges.

The true counterpart to a 0.06% yield on a bank account isn't the interest rate one can earn by on-lending stablecoins via protocols like Celsius or Compound. No, the proper analog is the interest rate one earns by simply holding a stablecoin such as Tether or USDC. And because stablecoin issuers don't pay interest to people who own stablecons, this rate is effectively 0%. Which is *ahem* below the 0.06% rate on a U.S. savings account.

Hardly a selling point. Unfortunately, the above chart forgets to mention the 0% rate on stablecoins.

Let me flesh this out further. When you own a stablecoin or keep money in a saving account, you are basically lending to the issuer of those dollars. If you hold 1,000 USDt (Tether stablecoins), for instance, you're a creditor to Tether Inc. That is, Tether Inc owes you $1,000. Likewise, if you keep $1,000 in a Bank of America savings account, you're lending $1,000 to Bank of America.

Think about this or a moment.

Lending involves risk. The borrowing party may not be able to keep its promise to you. Bank of America is a pretty safe entity to lend to. It'll probably keep its promise to you. But the firms that issue Tether and USDC are not safe borrowers. They are small. Not much is known about them. In Tether's case, it is entirely unregulated. And Circle, the issuer of USDC, is only lightly regulated. If you are acting as a lender to Tether or Circle, you should be getting *much* more than the 0% rate that they're offering you.

On top of that, your loan to Bank of America is protected by government insurance. Nothing protects your loan to Tether or Circle. Even worse, as a creditor to Tether and Circle, it's not apparent where you rank in terms of seniority. This ranking is important because in the case of a failure, senior creditors get paid first, junior creditors last. At least with a Bank of America account you're at the front of the line.

Far more prudent to lend to a government-insured bank and collect 0.06% than lend to a black box stablecoin and get 0%.

Of course, stablecoins aren't just held. It's what you can do with stablecoins that excites people. Which gets us to the massive crypto lending rates that are illustrated in the chart. Aave and Compound are decentralized lending protocols. If you on-lend your stablecoins via these two protocols, you can earn 2.69% to 3.14%.

Celsius, Nexo, and Blockfi are centralized marketplaces where rates for onlending stablecoins reach as high as 8.88%.

The thing is, you *should* be getting a high rate for onlending your stablecoins on these venues. You're taking a big risk by using them. These platforms could go broke, get hacked, or break. In the case of centralized platforms, there is very little information about how they are using your funds. Furthermore, you don't know where you stand in seniority among other Celsius, Nexo, or BlockFi creditors. These are black boxes, folks.

And remember, even though you've lent away your Tether or USDC on Celsius or Aave, you're still fully exposed to all the original credit risk of Tether or Circle. 

For instance, say you lend 1,000 USDt on Celsius's platform and Tether, the issuer of USDt, collapses. The price of USDt stablecoins falls from its $1 peg to $0.10. Celsius comes through, though. It keeps its promise to you and repays the 1000 USDt it owe you. Alas, now that amount is only worth $100.

So for DIY investors considering stablecoin lending strategies, any loan to Celsius or Aave involves a combination of two risks: the possibility that Tether or Circle (the issuer of USDC) go under and the chance that Celsius or Aave break. Add the two together and you're getting involved in a pretty dangerous strategy, one for which you should be well-compensated.

Rather than clapping your self on the back for getting 8% from stablecoins instead of 0.06% in a savings account, you should be asking yourself whether 8% is enough.

Thursday, April 29, 2021

Is DeFi unregulatable?


 Government's can't regulate DeFi, can they? It's too wild and uncontrollable.

DeFi, or decentralized finance, is the set of anarchic financial tools built on top of the Ethereum blockchain. These tools mimic what you'd see in the real world. MakerDAO is a decentralized bank, Compound and Aave are decentralized lending marketplaces (like Lending Tree), and Uniswap is an exchange, like the NASDAQ, except on a blockchain.

Unlike regular financial institutions, none of these Ethereum-based institutions operates with a license, registration, or a permit.

MakerDAO, for instance, recently financed some real world mortgages by issuing U.S. dollar deposits. So it seems to be operating as a commercial bank. However, MakerDAO hasn't secured a banking license from any of the world's biggest banking regulator, say OSFI, the FCA, OCC or any of the 50-some U.S. state financial departments.

Because DeFi is so new, it operates in a grey zone. On the one hand we can argue that the collection of smart contracts and governance mechanisms that comprises MakerDAO probably ought to do the bankerly thing and apply for a banking license. On the other hand there doesn't seem to be an express written rule about smart contracts on Ethereum requiring licensing.

But lets say that a bank regulator made an explicit announcement that MakerDAO and other DeFi tools acting as banks all had to get a license. Could MakerDAO get away without complying?

Because tools like MakerDAO are built on blockchains, and blockchains are too wild to be controlled, the theory is that there is no way for a regulator to exert sufficient pressure on the tool owners to instigate change. MakerDAO's owners will just laugh and keep doing what they've been doing. So would Aave, Uniswap and Curve. Smart contracts are just bits of unstoppable code, after all. They can't be punished for non-compliance. 

So DeFi is not only unregulated, goes the theory. It is unregulatable.

I think regulating DeFi would be fairly easy. U.S. regulators just announce "thou art now regulated and must comply with the following set of rules" and that'd be sufficient. Pretty soon, the biggest DeFi tools would fall into line.

Much of a regulator's leverage is exerted indirectly, via users. Even if the operators/administrators of major DeFi tools are against the idea of falling into line, their users will drag them towards it. 

Right now, the status of most DeFi tools is undefined. Users aren't doing anything illegal by interacting with them. They aren't doing anything legal, either. So people just shrug and use them. But regulation would change that status. Suddenly, tools and their users would be placed squarely in the illegal category, albeit with a pathway to legality.

U.S.-based financial institutions make up the largest group of financial tool users. And financial institutions generally prefer to avoid doing unlawful things, say like connecting to illegal financial tools. Retail customers, a less important customer group, are less picky. Some will do illegal things. But they mostly prefer to be on the side of the law.
 
That means any decentralized financial tool that wants to continue capturing the two biggest pools of money —institutional capital and licit retail funds—will have to make it legal for these users to connect to them. The proper licenses will have to be secured, regulatory-compliant smart contracts created, and a mechanism devised for users to port over. The biggest DeFi tools will choose to conform... if they want to stay the biggest.  

Sure, plenty of DeFi tools won't bother complying with regulation. But these tools will only end up appealing to an underground clientele, and that's always going to be a smaller market than the pool of licit users.

Network effects will be on the side of regulators. Read on...

There will always be DeFi users (traders, borrowers, liquidity providers, token issuers etc) who are indifferent between lawful DeFi tools or illegal tools. They just want to use the best ones. These agnostics will probably end up using the regulated tools by default. That's because the biggest pool of capital is always going to be licit capital that sticks to lawful trading venues. And so regulated DeFi tools will end up with the best liquidity, tightest spreads, and lowest fees. Hobbyists and criminals will put up with the low liquidity of unregulated DeFi, but everyone else's go-to choice will always be regulated DeFi.

This network effect operates in the same way as the U.S. government's decision to impose Daylight Savings Time. You may hate DST or you may be indifferent, you may not understand it or you may have forgotten about it. But come March 14 and November 7 you unfailingly move your clocks forward or backwards. Using a different clock than everyone else is just too much of a burden. Likewise, if the government announced a DST equivalent for DeFi, much of the space would get dragged, perhaps kicking and screaming, into a state of being standardized, or regulated. Remaining out-of-standard is too costly.

Regulated tools would probably stop interacting altogether with illegal tools. DeFi, currently an open playground, would further balkanize into underground DeFi and legit DeFi. Choosing underground DeFi would be an increasingly costly choice, since one risks being forever cut-off from legit DeFi.

So DeFi, or at least a big part of it, can probably be regulated. However, there will always be an unregulatable anarchic edge. Good luck stopping an Ethereum-based ponzi scheme, for instance. These are blockchains, after all. And they are open to everyone.

Saturday, March 6, 2021

Tether, a bigger badder PayPal

My recent article on Tether, a stablecoin, was just published at Coindesk. In the article I commented on Tether's recent settlement with the New York Attorney General's office. Because the settlement forces Tether to adopt a bunch of new practices, I think it's a win for stablecoin consumers.

Why have I been focusing so much of my time on Tether stablecoins? Diligent readers will recall I wrote about it twice last month. (1 | 2 ).

First, I've been writing about stablecoins for a long time now, and Tether has always been the biggest of the bunch. So it merits our attention. But it isn't just the biggest stablecoin. These days it's also becoming big by regular fintech standards. According to its website, Tether recently passed $35 billion in deposits, ranking it above PayPal's $34 billion. Which means that by my estimates it is now the largest U.S. dollar non-bank payments platform in the world ranked by customer funds.


Tether imprints dollars onto a blockchain. PayPal registers dollars in a centralized database. But apart from that, they're technically the same beast. Both keep some dollars (or not) on deposit with their banker and then issue dollar IOUs to their customers. And customers can in turn use these IOUs to make payments amongst each other.

The second reason I've been writing about Tether is that it is dubious. As I wrote here, it avoids U.S. money transmitter regulation by locating itself offshore. And it has somehow managed to wrest first spot away from PayPal despite doing very dangerous things with its customers' funds.

Its impropriety is a matter of public record. Even before last month's settlement with the New York Attorney General we already knew that, among other things, the firm had invested millions of dollars of customer money in a fraudulent third-party payments processor, all the while informing users that Tethers were backed by dollars "safely deposited in our bank accounts." If you want to get into this in more detail, Bennett Tomlin has been exploring these things in far more detail than I.

I am fascinated by this strange combination of popularity and sketchiness. And I'm not the only one. Tether analysis is a growing sub-field of cryptocurrency analysis.  

Tether is imbued with an aura of Trumpian invincibility. Hey, look at all these bad things we do. But we're getting away with it. The market keeps buying. We're bigger than PayPal! Tether's success makes outside observers wonder whether up is down, or bad is actually good.

But I want to dispel some of this seeming invincibility.

As I suggested in my Coindesk article, much of Tether's stablecoin dominance is probably due to network effects. That is, Tether was the first stablecoin to market, and so a Tether standard of sorts emerged. Like any standard, once everyone plugs into it it's hard to move away to a better standard. New and safer stablecoins—ones that have been licensed under a financial regulatory framework—have certainly emerged, including Paxos Standard, TrueUSD, Gemini Dollar, Binance USD, and USD Coin. But Tether enjoyed a four-year head-start, and so even if it murdered someone in the middle of 5th Avenue it would still be the leading stablecoin.

For instance, Tether is the only stablecoin that doesn't provide regular attestations.

Why doesn't Tether make an effort to adopt an industry-wide practice? It could be that it is just too sketchy to be able to hire an accounting firm to provide attestations. Alternatively, maybe its position as the standard stablecoin means it needn't bother. It gets to coast while everyone else has to peddle.

But if it's difficult to move away from a given standard, its not impossible. The first example that pops to mind is how the international monetary system was on a British sterling standard in the 1800s, but now we use U.S. dollars. Somehow sterling dominance evaporated. The same can happen with Tether's dominance.

In fact, I'd argue that we're already seeing a movement away from the Tether standard, particularly in decentralized finance, the set of financial protocols established on the Ethereum network.

It's hard to underestimate how much decentralized finance, or DeFi, dislikes Tether. Consider the biggest DeFi lending platforms, Compound and Aave. Both platforms allow USD Coin stablecoins to serve as collateral. (USD Coin is the second largest stablecoin). But these platforms say no to Tether. That is, if you want to get a loan from Compound or Aave, you can't use your stash of Tether as security. As I pointed out in my article, Compound's decision is based on reports that Tether is “undercollateralized” and has the “potential to collapse at any time.”

MakerDAO, a combined stablecoin/lending protocol and one of the top-three DeFi tools, has also adopted a say-no-to-Tether policy . It sets a hawkish 8% borrowing rate and 150% collateralization ratio on anyone who wants to take out a Tether-backed loan. That may sound like gibberish, so let me translate. For a $100 loan from Maker you've got to lock-up a hefty $150 in Tethers. You'll pay 8% in interest each year on the loan.

But if you want to take out a USD Coin-backed loan (remember, USD Coin is one of the newer safer coins), Maker's terms are far more dovish. It'll cost 0% and 101%. So to get a $100 loan, you need only provide $101 in USD Coin. And the interest costs is nil.

Given Maker's policy, there's absolutely no reason why you'd take out a Tether-backed loan rather than a USD Coin one. And that's why to this day Maker has a measly $700 in Tether sitting in its smart contracts versus a massive $700,000,000 in USD Coin. Below is an abridged list of collateral that has been deposited in Maker as security. The top red circle highlights how much USD Coin (USDC), that it holds. And the bottom circle indicates its Tether (USDT) holdings.

Source: Makerburn


It's worthwhile to revisit the policy meetings where Maker originally established its Tether policy. Citing Tether's "history of opaqueness and fractional reserve," administrators recommended conservative parameters in order to "protect Maker." At the same time, looser parameters were suggested for Paxos Standard stablecoins because it was "significantly more transparent."

In another discussion, Maker community members disapprovingly cited a tweet in which Stuart Hoegner, Tether's lawyer, jokes about Tether's approach to safeguarding customer funds. I've screenshotted it below.

Source: MakerDAO forum


Maker voters went on to approve a stringent approach to policing Tether, and rightly so given Tether's cavalier approach to managing customer funds. Defi grew exponentially in 2020. So did Maker. But almost all of its thirst for stablecoins was directed into non-Tether stablecoins. That's why there's still just $700 in Tether in Maker.

A back-of-the envelope calculation reveals how much money Tether may have missed out on. Had Tether taken pains to become safer to consumers, say by providing regular attestations and/or applying for a money transmitter license (like USD Coin and other competitors have done), it might have around $300 million Tethers sitting in Maker right now. Assuming that it invested this extra $300 million at an interest rate of 1%, Tether would be earning $3 million more each a year. 

And that's just one platform. Do the same for Compound, Aave, and more, and Tether's reputation has cost it tens of millions of dollars in profit.

Below I've charted out the ratio of the total value of all Tether stablecoins in existence to the total value of all USD Coins.The Tether-to-USDC ratio typically registered around 10 Tethers to each USDC through 2019 and early 2020, but this month it fell below 4 for the first time. USD Coin is steadily catching up to Tether for the title of largest stablecoin.


We all like the idea of justice. If you shoot someone in the middle of 5th Avenue, people should be appalled. In the case of a financial company, if you manage your customers' funds in a reckless manner and avoid informing them about the mistakes you made (and then joke about it after), then the market should discipline you, not reward you.

In the case of Tether, that is happening. As the chart above illustrates, Tether's poor stewardship of customer funds means that it is inexorably being replaced by safer stablecoins. Gresham's law, the adage that bad money pushes out good money, does not apply. The good is slowly pushing out the bad.

Saturday, August 31, 2019

Why the discrepancy?

Vitalik Buterin had a thought-provoking tweet a few days back about interest rates.
Today's post explores what goes into determining interest rates, not blockchain stuff. So for those who don't follow the blockchain world, let me get you up to speed by decoding some of the technical-ese in Buterin's tweet.

DAI is a version of the U.S. dollar. There are many versions of the dollar. The Fed issues both a paper and an electronic version, Wells Fargo issues its own account-based version, and PayPal does too. But whereas Wells Fargo and PayPal dollars are digital entries in company databases, and Fed paper dollars are circulating bearer notes, DAI is encoded on the Ethereum blockchain.

Buterin points out that DAI owners can lend out their U.S. dollar lookalikes on Compound, a lending protocol based on Ethereum, for 11.5%. That's a fabulous interest rate, especially when traditional dollar owner can only lend their dollars out to the government—the U.S. Treasury—at a rate of 1.5%.

Why this difference, asks Buterin?

Interest rates are a lot of fun to puzzle through. I had to think this one over for a bit—so let's slowly work through some of the factors at play.

Let's begin by flipping Buterin's question around. When the U.S. Treasury borrows from the public, the bonds it issues are promises to pay back regular dollars (i.e. Federal Reserve dollars). But what if the U.S. Treasury decided to borrow DAI by issuing bonds promising to repay in DAI? What would the interest rate on these Treasury DAI bonds be? Would it be 11.5% or 1.5%? Perhaps somewhere in between?

Credit risk

First, there's the question of credit risk. The U.S. Treasury is a very reliable debtor. It won't welch. If it issues both types of bonds, it'll be just as likely to repay its DAI bond as it will its regular dollar bond. Since the market already requires 1.5% from the Treasury to compensate it for credit risk (and a few other risks), the Treasury's DAI bonds should probably yield 1.5% too. (I'll modify this later as I add some more layers).

Now let's look at Compound. A DAI loan made on Compound (for simplicity let's just call it a Compound DAI bond) is surely much riskier than our hypothetical Treasury DAI bond. Compound is a blockchain experiment. It could malfunction due to buggy code. Maybe every single Compound borrower goes bust. To compensate for this risk, a prospective bond buyer will require a higher return from Compound DAI bonds than they will U.S. Treasury DAI bonds.

So Compound credit risk (Buterin's third option) probably explains a big chunk of the huge gap between the 11.5% interest rate on Compound DAI bonds and our hypothetical 1.5% interest rate on the U.S. Treasury's DAI bonds. But not all of it.

Collapse risk

Buterin mentions a second risk: the chance that DAI, the entity that creates blockchain dollars, collapses. Like Compound, DAI is a new monetary experiment. The code could be buggy. It might get hacked. By comparison, conventional dollar issuers—say Wells Fargo or PayPal—are far less likely to malfunction.

How does DAI collapse risk get built into the price of a hypothetical Treasury DAI bonds

The average market participant (I'm not talking about crypto fans here, but large & smart institutional actors) should be genuinely worried about purchasing a Treasury DAI bond—not so much because the Treasury is unlikely to pay it back—but because the DAI tokens that the Treasury ends up repaying could, in the even of DAI breaking, be worth 99% less than their original value. Average bond buyers will expect some compensation for bearing this risk. How much? Say 5.5% (I'm just guessing here).

Earlier I said that a Treasury DAI bond would yield 1.5%. But if we add 5.5% worth of failure risk to 1.5% in basic risk, a Treasury DAI bond should yield 7.0% before the average investor is going to hold it.

Now let's go back and look at a Compound DAI bond. As Buterin pointed out, they yield 11.5%, which is much higher than the 7.0% yield on our hypothetical Treasury DAI bond. We've already assumed that DAI collapse risk works out to 5.5%. If we subtract collapse risk from a Compound DAI bond's 11.5% yield, the remaining 6% is accounted for by risks such as Compound failing (11.5% - 5.5%). Put differently, investors in Compound DAI bonds will require 5.5% and 6.0% to compensate for collapse risk and credit risk respectively, for a total of 11.5%. Again, these are hypothetical numbers. But they help us puzzle things out.

Two different blockchain dollars: USDC vs DAI

Interestingly, Compound doesn't just facilitate DAI loans. It also expedites loans in another blockchain dollar, USDC. We'll refer to these as Compound USDC bonds. As Buterin points out later on in the thread, the rate on Compound USDC bonds is 6.5%, quite a bit lower than Compound DAI bonds.

What might explain this discrepancy?

Not credit risk, since in both instances the same creditor—Compound—is responsible for creating the bonds. Which leaves varying levels of collapse risk as an explanation. USDC is a regulated stablecoin (i.e. it has the government's approval). DAI isn't. And USDC has genuine U.S. dollars backing it, whereas DAI is backed by highly volatile cryptocurrencies. So the odds of USDC collapsing are surely lower than DAI.

How much interest do USDC bond holders require to compensate them for collapse risk? Assuming that Compound's risk of failing is worth 5.5% of interest (as we already claimed), that leaves just 1% attributable to the risk of USDC failing (6.5%-5.5%). Put differently, investors in Compound USDC bonds will require 5.5% and 1.0% to compensate for credit risk and collapse risk respectively, for a total of 6.5%.

Oddly, the yield on a Compound USCD bond is less than the hypothetical yield on our safe Treasury DAI bond (6.5% vs 7.0%). Why is that? Even though Compound is riskier to lend to than the Treasury, a DAI-linked return is riskier than a USDC return. Another way to think about this is that if the Treasury were to also issue USDC bonds, those bond would only yield 2.5%. To account for credit (and other) risks investors would require a base 1.5% with an extra 1.0% on top for the risk of USDC breaking.

The convenience yield

Let's bring in one last layer. Something called the convenience yield is lurking behind this.

When you lend me some tokens, you need to be compensated for more than just credit risk i.e. the risk that I won't pay back the tokens. You are also doing without the convenience of these tokens for a period of time. The replacement, my IOU, won't be very handy. For instance, the convenience of a dollar bill can be though of as the ability to mobilize it whenever you need to meet some pressing need. But if you've lent a $100 bill to me then you've given up all that bill's usefulness. Instead, you're stuck with my awkward $100 IOU. You need some compensation for this. (Unconvinced? Head over to Steve Randy Waldman's classic ode to the convenience yield).

So when we break down the components of the interest rate on DAI bonds, there must be some compensation required for forgoing the convenience of DAI, its convenience yield. Earlier I attributed the big gap between rates on Compound DAI and USDC bonds to varying odds of each scheme failing. However, the gap could also be explained by varying convenience yields. If the convenience yield of a DAI token is higher than that of a USDC token, we'd expect an issuer of a DAI bond to pay a higher rate than on a USDC bond, in order to compensate DAI holders for giving up on those superior conveniences. 

If DAI's convenience yield is higher than USDC's, what might explain this gap? DAI is completely decentralized and can't be monitored. USDC isn't. It is less censorship-resistant than DAI. So perhaps USDC just isn't as handy to have around.

So some of the 11.5% rate on Compound DAI bonds—say 2%—may be due to the convenience yield forgone on lent DAI. If DAI had the same features as USDC, and thus had a lower convenience yield, a Compound DAI bond might only yield 9.5% (11.5% - 2.0%). If so, the discrepancy between the Compound DAI and USDC bonds—9.5% vs 6.5%—wouldn't be as extreme.

Summing up, let's revisit Buterin's tweet:
If my line of thinking is right, the discrepancy is accounted for a messy mix of the higher risk of lending to Compound (3), the danger of DAI cracking (2), and whatever convenience yield one forgoes when one no longer has DAI on hand (4-other). And of course, Buterin's first option is right too. I'm assuming that people are rational and can easily buy and sell various assets. But the sorts of large institutional players who set market prices may not be operating in crypto markets.